The inventory Connector, explained

How the signed, outbound-only Connector collects your software inventory without opening any door into your site.

Expected result

You understand what the Connector reads, what it can never do, and how its data is verified.

Outbound-only by design

The Connector runs next to your site and pushes inventory outward. AegiFlow never logs into your server, and there is no inbound channel to abuse: if the Connector is off, the only consequence is stale inventory.

Signed and replay-protected

Every submission is signed and replay-protected. The platform accepts inventory only from the key you provisioned, and each batch records what was collected and when.

Read-only, bounded scope

The Connector reads software components - names and exact versions - so Threat Radar can answer relevance precisely. On the first production service it tracks 283 components. It does not modify files, execute remote commands or read content.

Freshness is part of the answer

Threat coverage conclusions carry the inventory timestamp they relied on. When inventory goes stale, conclusions demote to Unknown instead of pretending.

Verification

  • Inventory items appear with a fresh collection timestamp
  • Connector requests are signed and accepted